1200KM / detection
T1588.001 Malware — Detection Rules
Detection workspace for T1588.001 Malware: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Relevant ClamAV Message · stable · high · {"product":"linux","service":"clamav"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0845 Detection of Malware
AN1977 Analytic 1977
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle. Consider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific MaaS offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1588.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT1 · G0006
- Turla · G0010
- MuddyWater · G0069
- TA505 · G0092
- APT-C-36 · G0099
- BackdoorDiplomacy · G0135
- Andariel · G0138
- LazyScripter · G0140
- Aquatic Panda · G0143
- Ember Bear · G1003
- LAPSUS$ · G1004
- Earth Lusca · G1006
- Metador · G1013
- LuminousMoth · G1014
- Scattered Spider · G1015
- TA2541 · G1018
- UNC3886 · G1048
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.